The Agentic Economy Runs on Authority
Who gave your AI permission to act?
Watch any demo of agentic commerce this year and you’ll see the same show. An AI agent compares flights and books the trip. It notices a subscription about to renew, negotiates the price, and pays. It moves money between accounts to catch a better rate, then confirms the whole thing in a cheerful summary. The technology is genuinely impressive. And in every one of those demos, the most important question in the room is the one nobody asks on stage:
Who gave the agent permission to do that?
Not “how capable is the model.” Not “how clean is the integration.” Permission. Authority. The right to act, on someone’s behalf, with someone’s money and someone’s data, inside someone’s limits.
Software used to wait. Agents act.
For fifty years, enterprise software waited. It calculated, displayed, and suggested — and then a human clicked. A human approved the invoice, signed the order, moved the funds. Every control framework we have, from SOX to your expense policy, quietly assumes that a person is the thing that initiates.
Agents break that assumption. An agent initiates. It purchases the tickets, renews the policy, approves the invoice inside its threshold, rebalances the portfolio, and negotiates with a vendor’s agent that is negotiating right back. The moment software initiates, every action becomes a transaction of trust — and trust in an enterprise has always been governed by one thing: authority. Who may do what, with which resources, under which conditions, on whose account.
Identity gets most of the attention right now, and identity matters. But identity only answers who. Authority answers everything that actually determines risk: what you may do, how much, with which data, until when — and what happens the moment the answer changes.
Seven questions every board will ask
When agents act on behalf of your enterprise — or your customers — these are the questions your architecture has to answer. Not in a policy PDF. In the transaction path.
1. Who granted the authority? A named person, a role, a policy — something accountable. An agent acting on inherited defaults is an agent nobody actually authorized.
2. What exactly was granted? “Access to the finance system” is not an answer. Real authority is scoped to the action and the data element: read these fields and not those, move up to this amount, touch nothing marked restricted.
3. Under what conditions? Business hours. Approved counterparties. Price ceilings. Jurisdictions. Conditions are where intent lives, and an agent that ignores them is executing someone else’s intent, not yours.
4. For how long? Standing, open-ended authority is where incidents grow. Grants need expiry the way credit needs terms.
5. What happens to actions already in motion when authority is revoked? Revocation that only stops the next action is theater. The action already in flight is precisely the one you most need to stop.
6. Whose authority does an agent-to-agent transaction carry? When your agent transacts with a supplier’s agent, authority has to chain from a human grant through every hop — verifiably — or accountability dissolves at the first handoff.
7. Can you prove, afterward, that every action matched what was granted? Not logs of what happened — evidence of what was decided: a record of the authorization decision itself, made at the moment of the action, at the level of the data element.
Why this lands on the CFO’s desk
Auditors and regulators will not accept “the model decided.” When an agent approves an invoice or moves a deposit, a human still signs the quarter, and a named executive still owns the loss. That is why the first serious agentic incident at most companies won’t look like a hallucination. It will look like an agent doing exactly what it was allowed to do — because what it was allowed to do was never actually decided by anyone.
Consumer finance shows where this goes. When a customer’s agent shops deposit rates continuously, the bank stops winning the customer’s decision and starts winning the agent’s — every single day. The customer’s protection in that world is not the interface. It is the authority they granted: the limits, the conditions, the revocation, and the evidence that all of it held.
Authority as infrastructure
Every era of computing eventually turned its trust problem into infrastructure. Commerce on the open web was impossible until encryption became a protocol nobody thinks about. Card payments scaled because authorization, clearing, and dispute rights became shared rails rather than bilateral favors. The agentic economy needs the same thing for delegated authority:
Grants as first-class objects — created, scoped, expiring, revocable, and owned by someone. Decisions recorded as evidence — every authorization decision captured at the moment it is made, down to the specific data element and action. Revocation as a real control — one that reaches work already in flight. Delegation that chains — so an agent acting through other agents carries provable authority end to end.
This is a problem I’ve been working on in the open: a proposed extension to the Open Cybersecurity Schema Framework for recording authorization decisions as evidence, at the data element, is on GitHub — because evidence is what turns “we have policies” into “we can prove it.”
A year of enterprise rollouts has added a corollary I now test for everywhere: the gap between intended authorization and actual system capability. The policy says the agent may read the summary; the integration quietly lets it export the table. Paperwork describes intent — only runtime enforcement, observability, and reconstructable evidence describe exposure. And approval is never a one-time event: it attaches to a defined, time-bound system state, and a material change in model, data, scope, or autonomy is a trigger to reassess, restrict, or suspend.
What to do now
None of this requires waiting for a standard. Five moves any operator can start this quarter:
Inventory delegated authority. Every agent in production, every grant it runs on, every default it inherited. Most companies cannot produce this list today, and that fact is the finding.
Scope grants to actions and data elements, not systems. “The agent has API access” should be as unacceptable as “the new hire has all the keys.”
Make revocation real. Run the drill: revoke an agent’s authority mid-task and watch what happens to the work already moving. If the answer is “it completes,” you don’t have a control.
Demand decision evidence from every vendor. Ask to see the record of an authorization decision — who granted it, what was in scope, what the agent was allowed at the moment it acted. A demo of capability without evidence of authority is half a product.
Price authority like credit. Limits, terms, expiry, review. Treasury learned this a century ago; agent programs get to inherit it for free.
The question that defines the next decade
In the last platform shift, boards asked what AI could generate. In this one they will ask what we authorized it to do — and whether we can prove it. The companies that treat authority as infrastructure will move faster than the ones that treat it as paperwork, for the simplest of reasons: they can afford to delegate more.
The agentic economy will not run on intelligence. Intelligence is table stakes. It runs on authority.
This is the first essay in Field Notes on the Agentic Enterprise, a series on what enterprises must build as AI moves from generating to deciding to acting to transacting. Next: “Software Sold Seats. Cloud Sold Consumption. AI Will Sell Outcomes.”
Helping revenue leaders, founders, and investors build the future of go-to-market.
© 2026 Todd Yancey. All rights reserved.
